Search CVE reports


Toggle filters

1071 – 1080 of 41184 results

Status is adjusted based on your filters.


CVE-2026-32741

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mask image (mski), the function...

1 affected package

libheif

Package 20.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-32740

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of...

1 affected package

libheif

Package 20.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-32739

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero...

1 affected package

libheif

Package 20.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-41470

Medium priority
Needs evaluation

LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session...

1 affected package

liblivemedia

Package 20.04 LTS
liblivemedia Needs evaluation
Show less packages

CVE-2026-33642

Medium priority
Vulnerable

Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that...

1 affected package

kitty

Package 20.04 LTS
kitty Vulnerable
Show less packages

CVE-2026-33637

Medium priority
Needs evaluation

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 through 2.14.1 still allow protocol-relative host override when the request target is passed as a URI object...

1 affected package

ruby-faraday

Package 20.04 LTS
ruby-faraday Needs evaluation
Show less packages

CVE-2026-32738

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer underflow in the Chunk constructor...

1 affected package

libheif

Package 20.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-33633

Medium priority
Vulnerable

Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately....

1 affected package

kitty

Package 20.04 LTS
kitty Vulnerable
Show less packages

CVE-2026-8706

Medium priority
Ignored

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies....

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 20.04 LTS
firefox
mozjs102
mozjs115
mozjs38
mozjs52 Ignored
mozjs68 Ignored
mozjs78
mozjs91
thunderbird
Show all 9 packages Show less packages

CVE-2026-31072

Medium priority
Not affected

The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object function allows for arbitrary class...

1 affected package

apscheduler

Package 20.04 LTS
apscheduler Not affected
Show less packages